Cacti是Cacti团队的一套开源的网络流量监测和分析工具。该工具通过snmpget来获取数据,使用RRDtool绘画图形进行分析,并提供数据和用户管理功能。 Cacti存在安全漏洞,该漏洞源于存在反射型跨站脚本漏洞,允许攻击者获取管理员和其他用户的cookie,并使用获得的cookie伪造他们的登录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-29895 | 10.0 CRITICAL | Cacti command injection in cmd_realtime.php |
| CVE-2024-25641 | 9.1 CRITICAL | Cacti RCE vulnerability when importing packages |
| CVE-2024-34340 | 9.1 CRITICAL | Authentication Bypass when using using older password hashes |
| CVE-2024-31445 | 8.8 HIGH | SQL Injection vulnerability in automation_get_new_graphs_sql |
| CVE-2024-31459 | 8.1 HIGH | Cacti RCE vulnerability by file include in lib/plugin.php |
| CVE-2024-27082 | 7.6 HIGH | Cacti Cross-site Scripting vulnerability when managing trees |
| CVE-2024-31460 | 6.5 MEDIUM | Cacti SQL Injection vulnerability in lib/api_automation.php caused by reading dirty data s |
| CVE-2024-31443 | 5.7 MEDIUM | Cacti XSS vulnerability in lib/html_tree.php by reading dirty data stored in database |
| CVE-2024-29894 | 5.4 MEDIUM | Cacti Cross-site Scripting vulnerability when using JavaScript based messaging API |
| CVE-2024-31458 | 4.6 MEDIUM | Cacti SQL Injection vulnerability in lib/html_form_templates.php by reading dirty data sto |
| CVE-2024-31444 | 4.6 MEDIUM | Cacti XSS vulnerability in lib/html.php by reading dirty data stored in database |
No comments yet